Use GitHub's private vulnerability reporting / Security Advisories for this repository when available. Do not open a public issue for security-sensitive reports.
If private vulnerability reporting is unavailable, open a minimal public issue without exploit details and state that you can share additional information privately with maintainers.
This repository contains a research-stage, transport-only relay server for the QSL protocol project (see README.md). Report any issue that impacts the confidentiality, integrity, or availability of the artifacts in this repository.
Protocol-level reports (specifications, cryptography, the qsc client) belong to the qsl-protocol repository and its security policy.